PT-2026-96947 · Unknown · Mcp-Attlasian
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
A confused deputy issue exists where the server can be forced to read arbitrary local files and attach them to a Jira issue, leading to the exfiltration of sensitive host files and environment secrets. The problem occurs in the
update issue tool handler, where the attachments parameter is converted into local paths and routed to the upload implementation without workspace validation. The implementation fails to restrict paths to a safe workspace, prevent directory traversal using ../ sequences, or validate ownership. This allows a restricted agent to use the privileged MCP process to access system-level files, such as /proc/self/environ, and upload them to a Jira ticket.Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary workaround, avoid using the
attachments parameter in the update issue tool.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Attlasian